File name: | Minecraft Launcher by AnjoCaido.exe |
Full analysis: | https://app.any.run/tasks/7c27e396-54ae-458e-b2a5-3270410d3368 |
Verdict: | Malicious activity |
Analysis date: | July 26, 2019, 12:01:15 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
MD5: | 605A171C61A0607BDCF6BE80ED07CF95 |
SHA1: | 477D4391B0D84406127E43EAD289A3596AC1E5E5 |
SHA256: | 09B78DC85713CA0F27F17D94C939CC606A59847C1F2B5CDD281B52A48CDAEAB9 |
SSDEEP: | 6144:4mmx3k74XODG40zQG7NP0nuc6Hzp3wT66vlm4LbHL+pNn40yY7MmI2lP:ax3u9q400uB74fKL0m |
.exe | | | Win32 Executable MS Visual C++ (generic) (35) |
---|---|---|
.exe | | | Win64 Executable (generic) (30.9) |
.scr | | | Windows screen saver (14.6) |
.dll | | | Win32 Dynamic Link Library (generic) (7.3) |
.exe | | | Win32 Executable (generic) (5) |
InternalName: | MinecraftSP |
---|---|
OriginalFileName: | MinecraftSP.exe |
ProductVersion: | 12.1.2.0 |
ProductName: | MinecraftSP |
LegalCopyright: | 2010 AnjoCaido (but Mojang have the rights over the game, you pirate!) |
FileVersion: | 12.1.2.0 |
FileDescription: | Free launcher for Minecraft Alpha |
CompanyName: | AnjoCaido |
CharacterSet: | Unicode |
LanguageCode: | Neutral |
FileSubtype: | - |
ObjectFileType: | Unknown |
FileOS: | Win32 |
FileFlags: | Debug |
FileFlagsMask: | 0x0017 |
ProductVersionNumber: | 12.1.2.0 |
FileVersionNumber: | 12.1.2.0 |
Subsystem: | Windows GUI |
SubsystemVersion: | 4 |
ImageVersion: | 1 |
OSVersion: | 4 |
EntryPoint: | 0x11d8 |
UninitializedDataSize: | 50688 |
InitializedDataSize: | 494592 |
CodeSize: | 128000 |
LinkerVersion: | 2.56 |
PEType: | PE32 |
TimeStamp: | 2010:06:14 16:51:18+02:00 |
MachineType: | Intel 386 or later, and compatibles |
Architecture: | IMAGE_FILE_MACHINE_I386 |
---|---|
Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Compilation Date: | 14-Jun-2010 14:51:18 |
CompanyName: | AnjoCaido |
FileDescription: | Free launcher for Minecraft Alpha |
FileVersion: | 12.1.2.0 |
LegalCopyright: | 2010 AnjoCaido (but Mojang have the rights over the game, you pirate!) |
ProductName: | MinecraftSP |
ProductVersion: | 12.1.2.0 |
OriginalFilename: | MinecraftSP.exe |
InternalName: | MinecraftSP |
Magic number: | MZ |
---|---|
Bytes on last page of file: | 0x0090 |
Pages in file: | 0x0003 |
Relocations: | 0x0000 |
Size of header: | 0x0004 |
Min extra paragraphs: | 0x0000 |
Max extra paragraphs: | 0xFFFF |
Initial SS value: | 0x0000 |
Initial SP value: | 0x00B8 |
Checksum: | 0x0000 |
Initial IP value: | 0x0000 |
Initial CS value: | 0x0000 |
Overlay number: | 0x0000 |
OEM identifier: | 0x0000 |
OEM information: | 0x0000 |
Address of NE header: | 0x00000080 |
Signature: | PE |
---|---|
Machine: | IMAGE_FILE_MACHINE_I386 |
Number of sections: | 5 |
Time date stamp: | 14-Jun-2010 14:51:18 |
Pointer to Symbol Table: | 0x00000000 |
Number of symbols: | 0 |
Size of Optional Header: | 0x00E0 |
Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x0001F2B8 | 0x0001F400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.49943 |
.data | 0x00021000 | 0x000010B8 | 0x00001200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.32611 |
.bss | 0x00023000 | 0x0000C5F0 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.idata | 0x00030000 | 0x000014CC | 0x00001600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.8582 |
.rsrc | 0x00032000 | 0x00057000 | 0x00057000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.89004 |
Title | Entropy | Size | Codepage | Language | Type |
---|---|---|---|---|---|
1 | 4.95711 | 784 | UNKNOWN | UNKNOWN | RT_MANIFEST |
2 | 4.60877 | 67624 | UNKNOWN | UNKNOWN | RT_ICON |
3 | 4.97783 | 9640 | UNKNOWN | UNKNOWN | RT_ICON |
4 | 4.69194 | 4264 | UNKNOWN | UNKNOWN | RT_ICON |
5 | 5.0852 | 1128 | UNKNOWN | UNKNOWN | RT_ICON |
101 | 3.18197 | 302 | UNKNOWN | UNKNOWN | RT_DIALOG |
1001 | 2.6474 | 76 | UNKNOWN | UNKNOWN | RT_GROUP_ICON |
ADVAPI32.DLL |
COMCTL32.DLL |
KERNEL32.dll |
SHELL32.DLL |
USER32.dll |
msvcrt.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
3496 | "C:\Users\admin\AppData\Local\Temp\Minecraft Launcher by AnjoCaido.exe" | C:\Users\admin\AppData\Local\Temp\Minecraft Launcher by AnjoCaido.exe | explorer.exe | ||||||||||||
User: admin Company: AnjoCaido Integrity Level: MEDIUM Description: Free launcher for Minecraft Alpha Exit code: 0 Version: 12.1.2.0 Modules
| |||||||||||||||
1512 | c:\PROGRA~1\java\JRE18~1.0_9\bin\java.exe -version | c:\PROGRA~1\java\JRE18~1.0_9\bin\java.exe | — | Minecraft Launcher by AnjoCaido.exe | |||||||||||
User: admin Company: Oracle Corporation Integrity Level: MEDIUM Description: Java(TM) Platform SE binary Exit code: 0 Version: 8.0.920.14 Modules
| |||||||||||||||
3284 | javaw -Xms512m -Xmx1024m -Dsun.java2d.noddraw=true -Dsun.java2d.d3d=false -Dsun.java2d.opengl=false -Dsun.java2d.pmoffscreen=false -classpath /C:/Users/admin/AppData/Local/Temp/e4jF4C1.tmp_dir/MinecraftSP.jar net.minecraft.LauncherFrame | C:\ProgramData\Oracle\Java\javapath\javaw.exe | Minecraft Launcher by AnjoCaido.exe | ||||||||||||
User: admin Company: Oracle Corporation Integrity Level: MEDIUM Description: Java(TM) Platform SE binary Version: 8.0.920.14 Modules
| |||||||||||||||
1048 | C:\Users\admin\AppData\Local\Temp\i4jdel0.exe i4j8783478956860887305.tmp | C:\Users\admin\AppData\Local\Temp\i4jdel0.exe | — | Minecraft Launcher by AnjoCaido.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
|
(PID) Process: | (3496) Minecraft Launcher by AnjoCaido.exe | Key: | HKEY_CURRENT_USER\Software\ej-technologies\exe4j\jvms\c:/program files/java/jre1.8.0_92/bin/java.exe |
Operation: | write | Name: | LastWriteTime |
Value: 40942D4BC73ED401 | |||
(PID) Process: | (3496) Minecraft Launcher by AnjoCaido.exe | Key: | HKEY_CURRENT_USER\Software\ej-technologies\exe4j\jvms\c:/program files/java/jre1.8.0_92/bin/java.exe |
Operation: | write | Name: | Version |
Value: 1.8.0_92 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3496 | Minecraft Launcher by AnjoCaido.exe | C:\Users\admin\AppData\Local\Temp\e4jF4C2.tmp | — | |
MD5:— | SHA256:— | |||
3284 | javaw.exe | C:\Users\admin\AppData\Local\Temp\imageio8657407079661774774.tmp | — | |
MD5:— | SHA256:— | |||
3284 | javaw.exe | C:\Users\admin\AppData\Local\Temp\imageio3195663155004325281.tmp | — | |
MD5:— | SHA256:— | |||
3284 | javaw.exe | C:\Users\admin\AppData\Local\Temp\imageio4071061969623957433.tmp | — | |
MD5:— | SHA256:— | |||
3284 | javaw.exe | C:\Users\admin\AppData\Roaming\.minecraft\bin\windows_natives.jar.lzma | — | |
MD5:— | SHA256:— | |||
3284 | javaw.exe | C:\Users\admin\AppData\Roaming\.minecraft\bin\windows_natives.jar | — | |
MD5:— | SHA256:— | |||
3496 | Minecraft Launcher by AnjoCaido.exe | C:\Users\admin\AppData\Local\Temp\i4j8783478956860887305.tmp | binary | |
MD5:762C9B1362DF7AFD078225A67A49975A | SHA256:2711F0BFDE4A7D17A63510B05F25AD30D4183F3D52870F8179FCCCE675CC5CE1 | |||
3496 | Minecraft Launcher by AnjoCaido.exe | C:\Users\admin\.oracle_jre_usage\90737d32e3abaa4.timestamp | text | |
MD5:236160A75A8CC67739525E4BF87C8348 | SHA256:83AD88BE374E9D3480B4E8EFF4129B091166D1301FEFD6540884EBE9D91E554B | |||
3284 | javaw.exe | C:\Users\admin\.oracle_jre_usage\90737d32e3abaa4.timestamp | text | |
MD5:236160A75A8CC67739525E4BF87C8348 | SHA256:83AD88BE374E9D3480B4E8EFF4129B091166D1301FEFD6540884EBE9D91E554B | |||
3496 | Minecraft Launcher by AnjoCaido.exe | C:\Users\admin\AppData\Local\Temp\e4jF4C1.tmp_dir\exe4jlib.jar | java | |
MD5:C97D4F24CE40002EBDCBEB9148617E44 | SHA256:411F86A58A889912D462EAD6BF382547476787AEC915BCC047CE7638608531B9 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3284 | javaw.exe | HEAD | 200 | 52.216.171.109:80 | http://s3.amazonaws.com/MinecraftDownload/windows_natives.jar.lzma | US | — | — | shared |
3284 | javaw.exe | HEAD | 200 | 52.216.171.109:80 | http://s3.amazonaws.com/MinecraftDownload/lwjgl_util.jar | US | — | — | shared |
3284 | javaw.exe | HEAD | 200 | 52.216.171.109:80 | http://s3.amazonaws.com/MinecraftDownload/jinput.jar | US | — | — | shared |
3284 | javaw.exe | HEAD | 200 | 52.216.171.109:80 | http://s3.amazonaws.com/MinecraftDownload/minecraft.jar | US | — | — | shared |
3284 | javaw.exe | GET | 200 | 52.216.171.109:80 | http://s3.amazonaws.com/MinecraftDownload/jinput.jar | US | compressed | 222 Kb | shared |
3284 | javaw.exe | HEAD | 200 | 52.216.171.109:80 | http://s3.amazonaws.com/MinecraftDownload/lwjgl.jar | US | — | — | shared |
3284 | javaw.exe | GET | 200 | 52.216.171.109:80 | http://s3.amazonaws.com/MinecraftDownload/lwjgl_util.jar | US | compressed | 135 Kb | shared |
3284 | javaw.exe | GET | 200 | 52.216.171.109:80 | http://s3.amazonaws.com/MinecraftDownload/lwjgl.jar | US | compressed | 721 Kb | shared |
3284 | javaw.exe | GET | 200 | 52.216.171.109:80 | http://s3.amazonaws.com/MinecraftDownload/minecraft.jar | US | compressed | 5.31 Mb | shared |
3284 | javaw.exe | GET | 200 | 52.216.171.109:80 | http://s3.amazonaws.com/MinecraftDownload/windows_natives.jar.lzma | US | lzma | 479 Kb | shared |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3284 | javaw.exe | 52.216.171.109:80 | s3.amazonaws.com | Amazon.com, Inc. | US | shared |
Domain | IP | Reputation |
---|---|---|
s3.amazonaws.com |
| shared |
PID | Process | Class | Message |
---|---|---|---|
— | — | A Network Trojan was detected | ET INFO JAVA - Java Archive Download |
— | — | A Network Trojan was detected | ET INFO JAVA - Java Archive Download |
— | — | A Network Trojan was detected | ET INFO JAVA - Java Archive Download |